<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled Saved Search Retention in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Scheduled-Saved-Search-Retention/m-p/50950#M1094</link>
    <description>&lt;P&gt;Yes, the TTL setting for the alert overrides the setting in savedsearches.conf, but you should set the TTL in both places. The TTL in alert_actions.conf only applies if an alert is triggered, otherwise the TTL in savedsearches.conf applies.&lt;/P&gt;

&lt;P&gt;In both places, you can use the p notation or just the number of seconds to save.&lt;/P&gt;

&lt;P&gt;There are also settings for TTL in limits.conf, but those only apply to ad hoc searches.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2016 03:38:35 GMT</pubDate>
    <dc:creator>risgupta_splunk</dc:creator>
    <dc:date>2016-09-21T03:38:35Z</dc:date>
    <item>
      <title>Scheduled Saved Search Retention</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Saved-Search-Retention/m-p/50949#M1093</link>
      <description>&lt;P&gt;Hi~there,&lt;/P&gt;

&lt;P&gt;As I crawl related article, I know this can be done by adding dispatch.ttl=(int)p in savedsearches.conf and overwritten in alert_action.conf where p represents scheduled search's period, right? now i have one schedule saved search run on the 1st of each month. but i found its expired time just one day more after run time on job status. Is this normal or anything else? futhermore, if I do save job on job UI , does it mean eternal retention? next time when run this search again, will this be overwritten?&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2011 02:46:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Saved-Search-Retention/m-p/50949#M1093</guid>
      <dc:creator>hjwang</dc:creator>
      <dc:date>2011-08-01T02:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Saved Search Retention</title>
      <link>https://community.splunk.com/t5/Reporting/Scheduled-Saved-Search-Retention/m-p/50950#M1094</link>
      <description>&lt;P&gt;Yes, the TTL setting for the alert overrides the setting in savedsearches.conf, but you should set the TTL in both places. The TTL in alert_actions.conf only applies if an alert is triggered, otherwise the TTL in savedsearches.conf applies.&lt;/P&gt;

&lt;P&gt;In both places, you can use the p notation or just the number of seconds to save.&lt;/P&gt;

&lt;P&gt;There are also settings for TTL in limits.conf, but those only apply to ad hoc searches.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 03:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Scheduled-Saved-Search-Retention/m-p/50950#M1094</guid>
      <dc:creator>risgupta_splunk</dc:creator>
      <dc:date>2016-09-21T03:38:35Z</dc:date>
    </item>
  </channel>
</rss>

